Children’s privacy: COPPA, DPDP, and GDPR age gates
Minors’ data is not a smaller GDPR. It is a different regime — parental authority, restricted processing, and age assurance.

COPPA in the United States restricts collection from children under 13 without verifiable parental consent for many online services. GDPR sets a range of digital consent ages by Member State. India’s DPDP Act has specific rules for children and persons with disability, including guardian consent.
Age gates that simply ask “are you 18?” without any integrity checks will not carry a serious program.
Design for restriction
Default to the stricter path: disable behavioral ads, limit profiling, and route guardian workflows through a dedicated flow. Consent managers should support a child profile that cannot silently inherit an adult’s marketing opt-in.
Educational overview only — not legal advice. Confirm requirements with counsel for your products and markets.


